Cybersecurity 2026

SWITZERLAND Law and Practice Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd

they do not perform these tasks on the basis of a legal mandate. The NCSC is the key official actor in the cyberse - curity area. GovCERT.ch is the computer emergen - cy response team (CERT) for Switzerland. Its tasks include supporting the critical IT infrastructure in Swit - zerland in dealing with cyber threats. It maintains close relationships with other CERT organisations, thereby seeking to promote the exchange of cyber-threat- related information. Furthermore, the FDPIC retains strong prerogatives given the absence of standalone cybersecurity legislation. Given the federal system in Switzerland, it should also be borne in mind that other cantonal and inter-cantonal bodies serve the purpose of information sharing. This is notably the case for the inter-cantonal Swiss Crimi - nality Prevention Service (the SKP and PSC under its German or French and Italian acronyms, respectively). This service seeks to facilitate inter-cantonal police co-ordination as well as crime prevention measures. FINMA is the competent authority in the banking and financial sectors. As part of its statutory mission, and in the course of supervising regulated financial enti - ties, FINMA may also request compliance with appli - cable data protection and data security regulations. The Federal Office of Communications (OFCOM) is the federal office responsible for the proper imple - mentation of the legal and technical requirements in the communications realm and plays a particularly important role in the area of telecommunications. In the area of unfair competition, the State Secretariat for Economic Affairs (SECO) acts for the Swiss Con - federation in civil and criminal proceedings if matters of public interest are at stake. In addition, the following authorities may also be com - petent, albeit indirectly, in the cybersecurity area: • the Federal Office of Civil Aviation (in case of safety-related data breaches in the aviation sector); • the Federal Nuclear Safety Inspectorate (in case of sector-related data breaches);

• the Federal Department of the Environment, Trans - port, Energy and Communications (DETEC), espe - cially in regard to the national railway industry; and • Swissmedic, which receives notifications of seri - ous incidents that can include incidents relating to software as a medical device. 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation The ISA imposes a breach reporting obligation in the event of cyber-attacks affecting critical infrastructures. Moreover, the Federal Office for National Economic Supply (FONES) published a minimum information and communication technology (ICT) standard docu - ment as well as an ICT self-assessment tool directed at operators of critical infrastructures. This document rests, in part, on the requirements of the relatively ubiquitous National Institute of Standards and Tech - nology (NIST) framework to which it refers. 2.2 Critical Infrastructure Cybersecurity Requirements Concerning critical infrastructure cybersecurity requirements, see 2.1 Scope of Critical Infrastructure Cybersecurity Regulation . 2.3 Incident Response and Notification Obligations Concerning incident response and notification obliga - tions, see 2.1 Scope of Critical Infrastructure Cyber- security Regulation . 2.4 State Responsibilities and Obligations Concerning state responsibilities and obligations, see 2.1 Scope of Critical Infrastructure Cybersecurity Regulation .

379 CHAMBERS.COM

Powered by